×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cybersecurity Researcher Reverse Engineer

Job in Golden, Jefferson County, Colorado, 80401, USA
Listing for: National Renewable Energy Laboratory
Full Time position
Listed on 2026-07-02
Job specializations:
  • Engineering
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120400 - 216700 USD Yearly USD 120400.00 216700.00 YEAR
Job Description & How to Apply Below

Job Summary

Cybersecurity Researcher Reverse Engineer –

Location:

Golden, Colorado – Full‑time 40 hrs per week – Regular position at the National Laboratory of the Rockies (NLR).

Job Description

The National Laboratory of the Rockies (NLR) is seeking a skilled Cybersecurity Researcher Reverse Engineer to join our Cyber Threat Analysis Group within the Cybersecurity Research Center. This role requires candidates to analyze, deconstruct, and evaluate the security of highly complex embedded devices and systems critical to the nation’s energy infrastructure and national security. You will conduct deep‑dive vulnerability research on hardware and firmware found in Industrial Control Systems (ICS), smart grid components, electric vehicle supply equipment (EVSE), and distributed energy resources (DERs).

Drawing on a comprehensive understanding of system internals, cryptography, and network protocols, you will reverse engineer proprietary systems to uncover zero‑day vulnerabilities, develop reliable exploits in constrained environments, and design system‑level mitigations to secure the energy grid against advanced persistent threats (APTs).

Responsibilities
  • Design and deploy advanced discovery techniques against black‑box embedded systems.
  • Implement custom fuzzing harnesses for hardware‑in‑the‑loop and emulated environments.
  • Develop robust, weaponized proof‑of‑concept (PoC) exploits for constrained environments.
  • Bypass embedded exploit mitigations.
  • Write custom shellcode and achieve persistent execution within RTOS or bare‑metal environments.
  • Intercept, reverse engineer, and exploit communications across all layers.
  • Analyze local hardware buses (CAN, I2C, SPI), industrial control protocols (Modbus, DNP3, IEC
    61850 GOOSE/SV, CIP/Ether Net/IP), and modern Smart Grid/EV protocols (OCPP, IEEE
    2030.5, MQTT).
  • Perform static and dynamic analysis of compiled binaries, RTOS (e.g., VxWorks, QNX, FreeRTOS), and bare‑metal systems.
  • Reverse engineer boot sequences, evaluate kernel‑level internals, and identify privilege escalation vectors from user‑space tasks to the kernel or hypervisor.
  • Defeat hardware security mechanisms and extract firmware using debug interfaces (JTAG, UART, SWD).
  • Execute advanced hardware attacks, including side‑channel analysis and fault injection (glitching), to extract cryptographic keys or bypass authentication.
  • Translate highly technical vulnerability findings and exploitation mechanics into actionable intelligence.
  • Brief technical peers, leadership, and federal stakeholders on systemic risks to critical infrastructure and propose hardware/software mitigations.
Researcher IV

Solves uniquely significant problems: defeats advanced hardware security mechanisms (Secure Boot, Trust Zone) utilizing novel techniques like side‑channel analysis and fault injection; serves as a technical authority: briefs federal stakeholders and influences directorate‑level strategy; translates national needs: directly addresses national security priorities by developing advanced mitigations against APTs; drives lab‑wide capability: architects and maintains custom reverse engineering plugins and automation frameworks utilized by multiple teams;

mentors at the lab level: serves as a recognized expert, mentoring staff across the organization in highly specialized areas like kernel‑level privilege escalation and deep firmware analysis.

Researcher III

Solves complex problems: develops robust PoC exploits and performs deep static/dynamic analysis on constrained embedded environments; leads project‑level decisions: designs and deploys advanced vulnerability discovery techniques, including custom fuzzing harnesses and symbolic execution; applies broad engineering concepts: adapts established principles to bypass exploit mitigations (e.g., ASLR, DEP/NX) on ARM, MIPS, and PowerPC architectures; coordinates project efforts: guides the technical execution of intercepting and analyzing complex hardware buses (CAN, SPI) and industrial protocols (Modbus, DNP3);

represents the laboratory: translates highly technical vulnerability findings into actionable intelligence for internal peers and project leadership.

Qualifications
  • Researcher IV:
    • Relevant…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary